{"id":"GHSA-8wvg-r2j4-3737","summary":"Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint","details":"### Summary\n`TaskAssginee.ReadAll` returns assignee user objects without blanking the `Email` field, disclosing assignee email addresses to any read-only project member. Every sibling path that returns user objects obfuscates the email; this one does not.\n\n### Details\n`pkg/models/task_assignees.go` (~lines 306-344) does `Select(\"users.*\")` and returns the result directly. `User.Email` is `json:\"email,omitempty\"`, so a non-empty value always serializes. The endpoint gates on `task.CanRead`, so a read-only member passes. Sibling paths blank the field: `pkg/models/tasks.go:530`, `pkg/models/project_users.go:216`, `pkg/models/teams.go:177`, `pkg/models/label_task.go:312`, `pkg/models/task_attachment.go:511`. The omission here reads as an oversight, not a decision.\n\nThe same file's `getRawTaskAssigneesForTasks` (~line 56) also selects `users.*` but is safe because its only caller (`addAssigneesToTasks`) blanks the email afterwards.\n\n### PoC (verified at runtime against v2.5.0, v1 and v2)\n```\nGET /api/v1/tasks/{id}/assignees   (reader with permission:0)\n-\u003e [{\"id\":37,\"username\":\"...\",\"email\":\"assignee+SECRET@example.test\", ...}]\n```\nSame leak on `GET /api/v2/tasks/{id}/assignees` (routes through the identical model method). Contrast: `GET /api/v1/projects/{id}/projectusers` and the project task-embed both return the same users with no email.\n\n### Impact\nDisclosure of assignees' email addresses to users who should only see usernames. Read-only.\n\n### Fix\nBlank `Email` on each returned user in `TaskAssginee.ReadAll` before returning, matching the sibling paths. Covers v1 and v2 at once.","modified":"2026-10-09T21:00:09.306452139Z","published":"2026-10-09T20:54:49Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-09T20:54:49Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-8wvg-r2j4-3737"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/pull/3688"},{"type":"PACKAGE","url":"https://github.com/go-vikunja/vikunja"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/releases/tag/v2.6.0"}],"affected":[{"package":{"name":"code.vikunja.io/api","ecosystem":"Go","purl":"pkg:golang/code.vikunja.io/api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.5.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8wvg-r2j4-3737/GHSA-8wvg-r2j4-3737.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}